Top Free Android VPN Apps are Leaking Your Data, Study Finds

Advertisement
By Jamshed Avari | Updated: 22 January 2019 15:54 IST
Highlights
  • A huge number of apps either failed to work or had serious privacy issues
  • Many free VPN apps ask for permissions classified as 'dangerous'
  • Users who truly value their privacy and security should pay for a VPN

More than 25 percent of the 150 most popular free VPNs in the Google Play Store do not adequately protect users' privacy, and up to 85 percent of them open users up to various security vulnerabilities, according to a new study published by VPN reviews and advocacy site Top10VPN.com. The findings have been published in an exhaustive risk index that details each free VPN's real-world performance as well as behaviour, including the permissions they ask for and whether they potentially contain malware. The 150 free VPNs tested have been ranked on the basis of their total install base as reported on the Google Play Store.

The biggest problem identified is DNS leakage, which means that while network traffic such as the contents of Web pages and messages might be encrypted, the VPNs allowed DNS requests to be passed through a device's default configured DNS servers. This would allow a network operator such as an ISP to track the user's online activity, potentially defeating the purpose of the VPN itself.

Beyond that, 66 percent of the apps tested (99 in total) asked for unnecessary permissions that are classified as “dangerous” in official Android developer documentation. 25 percent of apps (38) asked to track location, while 38 percent (57) requested access to personal information on the Android device and a smaller unspecified number wanted to use the device's cameras and microphone or send text messages.

Advertisement

In total, 63 percent of the apps (95) were tagged in the report as featuring functions with the potential for privacy abuse. 18 percent (27) of the apps were flagged for potential viruses or malware when scanned.

Advertisement

The risk index does point out that simply asking for permissions does not mean that an app is malicious, but it is not very conducive to earning user trust. It could be a sign of sloppy practices on the part of the programmers, or it could be in order to help target the advertising that keeps these apps free. The risk index states that none of today's top paid VPN services require such permissions or contain such functions.

Several of the apps could not be fully tested for network security. 14 percent used DNS servers that have been blacklisted and 62 percent led users to blocked TCP ports, causing errors that prevented websites from loading. All of the apps that could be tested did successfully create encrypted VPN tunnels, but several of them did allow DNS leaks without any indication to the user, and two of the apps even leaked the test device's actual IP address, completely defeating the purpose of a VPN.

Advertisement

The top 10 free VPN apps by install base are HotSpotShield Free, SuperVPN, Hi VPN, HotSpotShield Basic, Psiphon Pro, Turbo VPN, VPN Master, Snap VPN, Hola, and Speed VPN, with between 10 million and 50 million users each. None were flagged for malware, but all were flagged for at least one of the core issues: risky permissions, risky functions, or DNS leakage.

Some of the VPN providers responded to Top10VPN.com's findings, and this has been factored into the risk index's findings and expressions of confidence written for each app. The exhaustive report with individual problem reports for each free app can be found here. Users who are concerned about privacy and security are advised that free VPNs might not be a viable option at all.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  2. AI Impact Summit: From Registration to Schedule, All You Need to Know
  3. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  4. Xiaomi 17 Series Leak Hints at Imminent Launch Ahead of MWC at These Prices
  5. PS6 Could Reportedly be Delayed to 2029 Due to RAM Shortage
  6. Poco X8 Pro Spotted on Geekbench With This Dimensity 8000 Series Chipset
  7. Deals on iPhone 17, Google Pixel 10 and More During Flipkart Sale
  1. Sony Could Reportedly Delay PS6 to as Late as 2029 Due to RAM Shortage
  2. iPhone 18 Series to Drop SIM Card Slot in Europe to Make Room for Slightly Larger Battery: Report
  3. Poco X8 Pro Spotted on Geekbench With MediaTek Dimensity 8500 Ultra SoC, Android 16
  4. Xiaomi 17, Xiaomi 17 Ultra Global Price Details, Launch Date and Colour Options Leaked
  5. X Building Smart 'Cashtags' to Let Users Check Cryptocurrency Prices in Real-Time
  6. Samsung Galaxy A27 5G Listing on IMEI Database Suggests a Galaxy A26 Successor Is on the Way
  7. Anthropic Inaugurates First Indian Office in Bengaluru, Starts Hiring Local Talent
  8. Apple Tipped to Adopt Samsung's Privacy Display Technology for MacBook Models by 2029
  9. Oppo Find X10 Series Tipped to Launch in H2 2026 With Built-In Magnets for Wireless Charging
  10. AMD and TCS to Co-Develop Helios AI Data Centre Architecture, Deliver 200MW Data Centre Blueprint
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.